Design a multi-domain or multi-forest Active Directory environment

Advanced
Administrator
Identity and Access Administrator
Windows Server

Learn how to extend a single-domain AD DS deployment when you need multiple domains or forests, complex delegation, trusts, advanced replication, or read-only domain controllers.

Learning objectives

In this module, you'll:

  • Determine when security isolation, legal separation, administrative autonomy, mergers, or replication constraints justify multiple domains or forests.
  • Design forest roots, domain trees, directory and application partitions, namespace coexistence, and global catalog scope.
  • Design OU structure, delegation, GPO scope and inheritance, protected objects, and schema governance.
  • Design trust direction, transitivity, selective authentication, SID filtering, SIDHistory governance, and cross-forest name resolution.
  • Plan universal group membership, global catalog placement, and authentication paths across domains and forests.
  • Analyze advanced replication risks and plan domain controller capacity and failure domains.
  • Design RODC branch deployments, including Password Replication Policy and delegated administration.

Prerequisites

  • Experience administering AD DS, including domain controller promotion, DNS, Group Policy, and PowerShell.
  • Familiarity with single-domain forest design, sites, and replication topology.